architect-review

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data such as design documents and codebases. This exposes the agent to indirect prompt injection where malicious instructions embedded in the analyzed data could attempt to manipulate behavior.
  • Ingestion points: Source code and documentation accessed via Read, Grep, and Glob tools as defined in the skill scope and metadata.
  • Boundary markers: Absent. The skill does not define specific delimiters or use instructions to treat external content as strictly data to be analyzed.
  • Capability inventory: The skill is restricted to read-only operations (Read, Grep, Glob) and lacks capabilities to write files, execute shell commands, or perform network requests.
  • Sanitization: No sanitization or filtering of external content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:53 PM
Security Audit — agent-trust-hub — architect-review